|
881
|
7.8 |
HIGH
Local
|
-
|
-
|
Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.
|
CWE-126
Buffer Over-read
|
CVE-2026-26184
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
882
|
4.4 |
MEDIUM
Local
|
-
|
-
|
Improper input validation in Windows Hello allows an authorized attacker to bypass a security feature locally.
|
CWE-20
Improper Input Validation
|
CVE-2026-27906
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
883
|
7.8 |
HIGH
Local
|
-
|
-
|
Integer underflow (wrap or wraparound) in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2026-27907
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
884
|
7.0 |
HIGH
Local
|
-
|
-
|
Use after free in Windows TDI Translation Driver (tdx.sys) allows an authorized attacker to elevate privileges locally.
|
CWE-416
Use After Free
|
CVE-2026-27908
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
885
|
7.8 |
HIGH
Local
|
-
|
-
|
Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
|
CWE-416
Use After Free
|
CVE-2026-27909
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
886
|
7.8 |
HIGH
Local
|
-
|
-
|
Improper handling of insufficient permissions or privileges in Windows Installer allows an authorized attacker to elevate privileges locally.
|
CWE-280
Improper Handling of Insufficient Permissions or Privileges
|
CVE-2026-27910
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
887
|
7.8 |
HIGH
Local
|
-
|
-
|
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally.
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2026-27911
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
888
|
8.0 |
HIGH
Adjacent
|
-
|
-
|
Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network.
|
CWE-285
Improper Authorization
|
CVE-2026-27912
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
889
|
7.7 |
HIGH
Local
|
-
|
-
|
Improper input validation in Windows BitLocker allows an unauthorized attacker to bypass a security feature locally.
|
CWE-20
Improper Input Validation
|
CVE-2026-27913
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
890
|
7.8 |
HIGH
Local
|
-
|
-
|
Improper access control in Microsoft Management Console allows an authorized attacker to elevate privileges locally.
|
CWE-284
Improper Access Control
|
CVE-2026-27914
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|